peter bassill · operator
$ cve CVE-2018-1000613 JSON

CVE-2018-1000613

9.8
CRITICAL · CVSS 3.1 · EPSS 4.8% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.77% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-470
On CISA KEVno
Public exploitnone known
Published2018-07-09
Last modified2026-06-17

Affected (24)

VendorProduct
bouncycastlebc-java
netapponcommand workflow automation
opensuseleap
oracleapi gateway
oraclebanking platform
oraclebusiness process management suite
oraclebusiness transaction management
oraclecommunications application session controller
oraclecommunications converged application server
oraclecommunications convergence
oraclecommunications diameter signaling router
oraclecommunications webrtc session controller
oracledata integrator
oracleenterprise manager base platform
oracleenterprise manager for fusion middleware
oracleenterprise repository
oraclemanaged file transfer
oraclepeoplesoft enterprise peopletools
oracleretail convenience and fuel pos software
oracleretail xstore point of service
oraclesoa suite
oracleutilities network management system
oraclewebcenter portal
oracleweblogic server

References

→ the Explorer  ·  watch your stack  ·  NVD